Vulnerability Name:

CVE-2016-9536 (CCN-119241)

Assigned:2016-09-24
Published:2016-09-24
Updated:2018-01-05
Summary:tools/tiff2pdf.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers in t2p_process_jpeg_strip(). Reported as MSVR 35098, aka "t2p_process_jpeg_strip heap-buffer-overflow."
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
6.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)
5.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
7.0 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
6.1 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
5.1 Medium (REDHAT CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-787
CWE-119
CWE-122
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2016-9536

Source: CCN
Type: RHSA-2017-0225
Moderate: libtiff security update

Source: REDHAT
Type: UNKNOWN
RHSA-2017:0225

Source: DEBIAN
Type: UNKNOWN
DSA-3762

Source: CCN
Type: LibTIFF Web Site
LibTIFF

Source: BID
Type: Third Party Advisory, VDB Entry
94484

Source: CCN
Type: BID-94484
RETIRED: LibTIFF Multiple Security Vulnerabilites

Source: BID
Type: UNKNOWN
94745

Source: CCN
Type: BID-94745
LibTIFF CVE-2016-9536 Heap Buffer Overflow Vulnerability

Source: XF
Type: UNKNOWN
libtiff-cve20169536-bo(119241)

Source: CCN
Type: LibTIFF GIT Repository
tools/tiffcrop.c: fix various out-of-bounds write vulnerabilities

Source: CONFIRM
Type: Issue Tracking, Patch, Third Party Advisory
https://github.com/vadz/libtiff/commit/83a4b92815ea04969d494416eaae3d4c6b338e4a#diff-5173a9b3b48146e4fd86d7b9b346115e

Source: CCN
Type: Apple security document HT207615
About the security content of macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2016-9536

Vulnerable Configuration:Configuration 1:
  • cpe:/a:libtiff:libtiff:4.0.6:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:6::client:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:6::computenode:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:6::workstation:*:*:*:*:*

  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*

  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*

  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*

  • Configuration RedHat 9:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*

  • Configuration RedHat 10:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:libtiff:libtiff:4.0.6:*:*:*:*:*:*:*
  • AND
  • cpe:/o:redhat:enterprise_linux_desktop:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_hpc_node:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_hpc_node:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server_tus:7.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20169536
    V
    CVE-2016-9536
    2022-05-20
    oval:org.opensuse.security:def:29495
    P
    Security update for net-snmp (Important)
    2022-01-05
    oval:org.opensuse.security:def:35280
    P
    Security update for libqt4 (Important)
    2021-12-22
    oval:org.opensuse.security:def:31334
    P
    Security update for log4j (Important)
    2021-12-17
    oval:org.opensuse.security:def:30283
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:34590
    P
    Security update for MozillaFirefox (Important)
    2021-11-17
    oval:org.opensuse.security:def:31700
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:29441
    P
    Security update for binutils (Moderate)
    2021-11-02
    oval:org.opensuse.security:def:30115
    P
    Security update for cpio (Important)
    2021-08-23
    oval:org.opensuse.security:def:31247
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-08-20
    oval:org.opensuse.security:def:34500
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:33694
    P
    Security update for libsndfile (Critical)
    2021-08-05
    oval:org.opensuse.security:def:31656
    P
    Security update for systemd (Important)
    2021-07-21
    oval:org.opensuse.security:def:30104
    P
    Security update for systemd (Important)
    2021-07-21
    oval:org.opensuse.security:def:30103
    P
    Security update for the Linux Kernel (Important)
    2021-07-20
    oval:org.opensuse.security:def:32949
    P
    Security update for webkit2gtk3 (Important)
    2021-06-17
    oval:org.opensuse.security:def:36429
    P
    kopete-devel-4.3.5-0.4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36387
    P
    cvs-doc-1.12.12-144.23.5.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:31634
    P
    Security update for qemu (Important)
    2021-06-08
    oval:org.opensuse.security:def:31190
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:34443
    P
    Security update for postgresql12 (Moderate)
    2021-05-27
    oval:org.opensuse.security:def:33650
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:30189
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:33084
    P
    Security update for tomcat (Moderate)
    2021-02-25
    oval:org.opensuse.security:def:28929
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP2) (Important)
    2021-02-10
    oval:org.opensuse.security:def:33626
    P
    Security update for xen (Moderate)
    2020-12-22
    oval:org.opensuse.security:def:31098
    P
    Security update for MozillaFirefox (Critical)
    2020-12-21
    oval:org.opensuse.security:def:34332
    P
    Security update for curl (Moderate)
    2020-12-10
    oval:org.opensuse.security:def:28860
    P
    Security update for mutt (Important)
    2020-12-07
    oval:org.opensuse.security:def:35644
    P
    tar-1.20-23.23.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35603
    P
    libsnmp15-32bit-5.4.2.1-8.2.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35749
    P
    libgtop-2.28.0-1.2.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35705
    P
    gd-2.0.36.RC1-52.18 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35677
    P
    clamav-0.97.3-0.2.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35638
    P
    squid-2.7.STABLE5-2.4.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35589
    P
    libltdl7-2.2.6-2.131.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35530
    P
    clamav-0.96-0.12.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:26976
    P
    libtspi1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33236
    P
    ppc64-diag on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29583
    P
    Security update for apache2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26965
    P
    libproxy0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33179
    P
    libsamplerate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29544
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26964
    P
    libpoppler-glib4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34965
    P
    Security update for fuse (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34921
    P
    Security update for evolution-data-server
    2020-12-01
    oval:org.opensuse.security:def:32870
    P
    glibc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29288
    P
    Security update for OFED
    2020-12-01
    oval:org.opensuse.security:def:34895
    P
    Security update for cyrus-imapd (Important)
    2020-12-01
    oval:org.opensuse.security:def:32859
    P
    file-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29203
    P
    Security update for openssl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34856
    P
    Security update for cifs-utils (Important)
    2020-12-01
    oval:org.opensuse.security:def:31592
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32858
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29146
    P
    Security update for kvm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34807
    P
    Security update for apache2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31554
    P
    Security update for sqlite3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29060
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:34749
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:30916
    P
    Security update for gcc48 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30872
    P
    Security update for expat (Important)
    2020-12-01
    oval:org.opensuse.security:def:30852
    P
    Security update for djvulibre (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28849
    P
    Security update for xalan-j2
    2020-12-01
    oval:org.opensuse.security:def:30813
    P
    Recommended udpate for SUSE Manager Client Tools (Low)
    2020-12-01
    oval:org.opensuse.security:def:28848
    P
    Security update for wpa_supplicant (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34345
    P
    Security update for squid3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:30764
    P
    Security update for apport (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34209
    P
    Security update for perl-PlRPC (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30709
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:34125
    P
    Security update for netpbm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30554
    P
    Security update for libqt4
    2020-12-01
    oval:org.opensuse.security:def:34114
    P
    Security update for nagios (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30467
    P
    Security update for apache2-mod_nss
    2020-12-01
    oval:org.opensuse.security:def:32377
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34113
    P
    Security update for mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30410
    P
    Security update for xorg-x11-libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32338
    P
    Security update for sblim-sfcb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30321
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35370
    P
    Security update for net-snmp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35223
    P
    Security update for liblouis (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31595
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28413
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35122
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31546
    P
    Security update for sane-backends (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28378
    P
    Security update for quagga (Important)
    2020-12-01
    oval:org.opensuse.security:def:34986
    P
    Security update for giflib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31490
    P
    Security update for python (Important)
    2020-12-01
    oval:org.opensuse.security:def:27740
    P
    Security update for MozillaFirefox, mozilla-nspr (Important)
    2020-12-01
    oval:org.opensuse.security:def:34902
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27696
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:34891
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:27682
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:34372
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34890
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:27643
    P
    Security update for libssh2
    2020-12-01
    oval:org.opensuse.security:def:27594
    P
    Security update for GraphicsMagick
    2020-12-01
    oval:org.opensuse.security:def:30966
    P
    Security update for grub2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27541
    P
    pwlib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30892
    P
    Security update for MozillaFirefox, mozilla-nspr (Important)
    2020-12-01
    oval:org.opensuse.security:def:27390
    P
    dhcp-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30881
    P
    Security update for file-roller (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27306
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33587
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:30320
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30880
    P
    Security update for file
    2020-12-01
    oval:org.opensuse.security:def:27249
    P
    ntp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33538
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:27168
    P
    ldapsmb on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33481
    P
    Security update for libnetpbm
    2020-12-01
    oval:org.opensuse.security:def:29645
    P
    Security update for cups (Important)
    2020-12-01
    oval:org.opensuse.security:def:27040
    P
    systemtap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33324
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29601
    P
    Security update for automake
    2020-12-01
    oval:org.cisecurity:def:1756
    P
    DSA-3762-1 -- tiff -- security update
    2017-02-24
    oval:com.redhat.rhsa:def:20170225
    P
    RHSA-2017:0225: libtiff security update (Moderate)
    2017-02-01
    oval:com.ubuntu.precise:def:20169536000
    V
    CVE-2016-9536 on Ubuntu 12.04 LTS (precise) - low.
    2016-11-22
    oval:com.ubuntu.trusty:def:20169536000
    V
    CVE-2016-9536 on Ubuntu 14.04 LTS (trusty) - low.
    2016-11-22
    oval:com.ubuntu.xenial:def:201695360000000
    V
    CVE-2016-9536 on Ubuntu 16.04 LTS (xenial) - low.
    2016-11-22
    oval:com.ubuntu.xenial:def:20169536000
    V
    CVE-2016-9536 on Ubuntu 16.04 LTS (xenial) - low.
    2016-11-22
    BACK
    libtiff libtiff 4.0.6
    libtiff libtiff 4.0.6
    redhat enterprise linux desktop 7
    redhat enterprise linux hpc node 7
    redhat enterprise linux server 7
    redhat enterprise linux workstation 7
    redhat enterprise linux desktop 6
    redhat enterprise linux hpc node 6
    redhat enterprise linux server 6
    redhat enterprise linux workstation 6
    redhat enterprise linux server tus 7.3